Privacy policy
Last updated 3 August 2026
This explains what Fariin stores, what it cannot read, which permissions it asks your phone for, who else touches your data, and how to get rid of all of it. It is written to be read, not to be survived.
The short version
The contents of your messages and calls are encrypted so that only you and the person you are talking to can read or hear them. We cannot. What we hold is the small amount of information needed to run an account and deliver a message: who you are, which devices you use, and when something was sent.
We have never sold data about you and we will not. There are no ads in Fariin, no advertising companies in it, and nothing in this policy permits anyone to buy access to you.
Permissions the app asks for
iOS asks before Fariin can touch any of these, and you can say no to every one of them. Saying no switches off the feature that needs it and nothing else. You can change your mind later in the iPhone Settings app under Fariin.
| Permission | Asked when | What it is used for |
|---|---|---|
| Photos | The first time you attach a picture | Reading the picture you picked. Fariin does not scan your library or look at photos you did not choose. |
| Save to photos | The first time you save a picture from a chat | Writing that one picture to your camera roll. |
| Camera | The first time you take a photo in a chat or start a video call | Taking the photo, and your video during a call. |
| Microphone | The first time you record a voice message or start a call | Recording that message, and your voice during a call. |
| Location | Only if you choose to send a location | Reading your position once so it can be put in that message. Fariin does not track you in the background and does not ask for always-on location. |
| Face ID | Only if you turn on the app lock | Unlocking the app. The check happens on your phone and Fariin never receives your face data. |
| Notifications | When you first sign in | Waking your phone for a message or an incoming call. |
Fariin never asks for your contacts. Your address book is not read and not uploaded. Most messengers upload it to work out who you know. This one does not, so there is no copy of your social circle on our servers to lose, subpoena or leak.
What we store
Your account
A username, a display name, and the phone number or email address you signed up with. If you add a profile photo, that too.
Your profile photo and display name are not end to end encrypted. They have to be readable by people allowed to see your profile, so treat them as visible to anyone you chat with.
Messages and media
Message text is encrypted on your phone before it leaves and decrypted on the recipient's phone. We store the encrypted result so it can be delivered, plus what is needed to deliver it: who sent it, who it is for, and when. Photos, video, voice notes and files are handled the same way. If you turn on disappearing messages, the message is removed when the timer runs out.
Calls
Voice and video are encrypted between the two phones. Most calls connect directly. When two phones cannot reach each other, which is common on mobile networks, the encrypted audio and video is relayed through a server so the call can happen at all. The relay passes it on and cannot open it. We keep a record that a call took place, between whom, and how long it lasted.
Stories
Visible to the people you choose for twenty four hours, then deleted. We record who viewed it so you can see that list.
Devices and sign ins
A notification token for each device you sign in on, so your phone can be woken. A short record of your devices, so we can email you when a new one signs in. That email includes the time, the device type and the IP address the sign in came from. We read the IP from the connection itself rather than from anything the app claims, so a modified client cannot fake it.
What we never collect
- Your contacts or address book.
- Your location, unless you deliberately send one in a message.
- Advertising identifiers. There are no ads and no ad networks in the app.
- Any profile of you built to sell, target or score you.
- The contents of your messages and calls, which we cannot read.
Why we are allowed to hold it
Under UK and EU data protection law every piece of processing needs a lawful basis. Ours:
| What | Lawful basis |
|---|---|
| Your account, and delivering your messages and calls | Performance of a contract. You asked us to run a messenger for you and this is the minimum needed to do it. |
| Notification tokens | Performance of a contract. Without them your phone cannot ring. |
| New device emails and abuse handling | Legitimate interests, specifically keeping accounts secure and the service usable. You can object, see your rights below. |
| Camera, photos, microphone, location, Face ID | Consent, given through the iOS permission prompt, withdrawable at any time in Settings. |
| Keeping records where the law requires it | Legal obligation. |
Companies that process data for us
Fariin does not own server hardware. These are the services it runs on and what each one touches. Each is bound by a contract that permits them to act only on our instructions and forbids using your data for their own purposes.
| Service | What it handles |
|---|---|
| Google Firebase | Accounts, the message database, file storage. Message contents arrive already encrypted. |
| Apple Push Notification service | Waking your iPhone for a message or an incoming call. |
| Cloudflare | Relaying calls that cannot connect directly, and serving this website. |
| LiveKit | Group calls with more than two people. |
| Resend | Sending the account emails described above. |
| Giphy | GIF search. What you type into GIF search is sent to Giphy. |
Nobody else receives your data. We do not sell it, rent it, trade it, or hand it to advertisers or data brokers. If we are ever served a valid legal order we will comply with it, and what we can hand over is limited to what we hold, which does not include the contents of your messages or calls.
Where your data is held, and transfers
The message database and file storage run in Google's Middle East region. Account emails are processed in Ireland. Call relays run on servers near whoever is calling, including Mogadishu, Djibouti and Nairobi.
That means data about people in the UK or the EU can leave those regions. Where it does, the transfer relies on the UK and EU Standard Contractual Clauses in our agreements with the providers above, or on an adequacy decision where one covers the country in question.
How long we keep things
- Messages stay until you or the other person deletes them, or a disappearing timer removes them.
- Stories are deleted after twenty four hours. Their view lists go with them.
- Device and notification records are kept while that device is signed in, and removed when it signs out.
- Everything else goes when your account does, subject to the thirty days below.
How it is protected
- Message and call contents are encrypted end to end. The key that opens them exists only on the phones involved.
- Everything in transit is encrypted in the usual way as well, so the encrypted payload is itself carried over an encrypted connection.
- Access to the servers is limited to the person who runs Fariin, protected by two factor authentication.
- Database rules are written so that one account cannot read another's data even if the app is modified. The server enforces this rather than trusting the app.
No system is beyond breaking, and anyone who tells you otherwise is selling something. What end to end encryption buys you is that a breach of our servers still does not expose what you said.
If something goes wrong
If there is a breach that puts your data at risk, we will report it to the relevant supervisory authority within 72 hours of becoming aware of it, as the law requires, and tell you directly and without delay if the risk to you is high. We will say what happened, what was affected, and what to do about it. We will not quietly sit on it.
Deleting your account
You can delete your account from inside the app. We email you, then wait thirty days before erasing anything, so a deletion made in anger or by accident can be undone. Signing back in during those thirty days cancels it.
After thirty days we delete your stories and their media, your profile photo, your account record, and your sign in credentials. Messages you already sent to other people stay on their phones, the way a letter you posted stays with whoever received it.
Your rights
If you are in the UK or the EU, the law gives you all of the following. In practice we honour them for everyone, wherever you live.
- Access. Ask what we hold about you and get a copy.
- Portability. Get that copy in a form you can take elsewhere.
- Correction. Have anything wrong put right.
- Deletion. Have it erased. The app does this itself.
- Restriction. Ask us to hold it but stop using it while a dispute is sorted out.
- Objection. Object to anything we do on the basis of legitimate interests.
- Withdrawing consent. Turn off any permission in iOS Settings at any time. It takes effect immediately and does not undo what was already done lawfully.
Write to [email protected] and we will answer within thirty days. There is no charge. If you are not satisfied with our answer you can complain to your national data protection authority, which in the UK is the Information Commissioner's Office.
Children
Fariin is not intended for children under 13. We do not knowingly hold data about them. If we learn an account belongs to a child under 13 we delete it. If you believe that has happened, write to [email protected].
This website
fariin.com sets no cookies, runs no analytics, and carries no trackers or third party scripts. Nothing here follows you. Our host keeps standard server logs, including IP addresses, for a short period to serve pages and absorb attacks.
Automated decisions
Nothing about your account is decided by an automated system, and there is no profiling.
Who is responsible for your data
Fariin is run by one person rather than a company. They are the data controller for the purposes of the UK and EU rules and can be reached at [email protected]. If a postal address is needed for a formal request, ask and it will be provided. If Fariin becomes a registered company this page will name it.
Changes to this policy
If this changes in a way that affects you, we will tell you in the app before it takes effect, not afterwards. The date at the top always reflects the version you are reading.
Contact
Write to [email protected]. To report abuse, write to [email protected].